<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<rss version="2.0" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/">
<channel>
<title>newz.dk - Nyheder - Ukendt programmeringssprog brugt i Duqu-trojaner</title>
<link>http://newz.dk/</link>
<description>nyheder for rigtige nørder</description>
<language>da</language>
<copyright>Copyright 2013, newz.dk</copyright>
<managingEditor>redaktionen@newz.dk(Redaktionen)</managingEditor>
<webMaster>teknik@newz.dk (Teknik)</webMaster>
<pubDate>Mon, 19 Mar 2012 20:32:58 +0100</pubDate>
<lastBuildDate>Mon, 19 Mar 2012 20:32:58 +0100</lastBuildDate>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<atom:link href="http://newz.dk/news/item/121189/rss" rel="self" type="application/rss+xml" />
<image>
<title>newz.dk - Nyheder - Ukendt programmeringssprog brugt i Duqu-trojaner</title>
<url>http://newz.dk/gfx/newz-dk/newz-dk/logo.png</url>
<link>http://newz.dk/</link>
</image>
<item>
<title>#5 - tormok</title>
<link>http://newz.dk/ukendt-programmeringssprog-brugt-i-duqu-trojaner#5</link>
<description><![CDATA[<p>Igor Soumenkov fra Kaspersky har skrevet en ny blogpost om det "ukendte" programmeringssprog.</p><blockquote cite="http://www.securelist.com/en/blog/677/The_mystery_of_Duqu_Framework_solved"><p><strong>The mystery of Duqu Framework solved</strong></p><p>In my previous blogpost about the Duqu Framework, I described one of the biggest remaining mysteries about Duqu – the oddities of the C&C communications module which appears to have been written in a different language than the rest of the Duqu code. As technical experts, we found this question very interesting and puzzling and we wanted to share it with the community.</p><p>...</p><p>So, what does that mean? In short, there are two very probable answers to our initial question:</p><p>1. The code was written using a custom OO C framework, based on macros or custom preprocessor directives. This was suggested by your comments, because it is the most common way to combine object-oriented programming with C.</p><p>2. All the code was written in OO C manually, without any extensions to the language. We can’t deny this possibility completely because, technically, it is near impossible to distinguish code written with macro directives from manually copy-pasted code.</p><p>...</p><p>Conclusions</p><p>- The Duqu Framework consists of “C” code compiled with MSVC 2008 using the special options “/O1” and “/Ob1”<br/>- The code was most likely written with a custom extension to C, generally called “OO C”<br/>- The event-driven architecture was developed as a part of the Duqu Framework or its OO C extension<br/>- The C&C code could have been reused from an already existing software project and integrated into the Duqu trojan</p><p>All the conclusions above indicate a rather professional team of developers, which appear to be reusing older code written by top “old school” developers. Such techniques are normally seen in professional software and almost never in today’s malware. Once again, these indicate that Duqu, just like Stuxnet, is a “one of a kind” piece of malware which stands out like a gem from the large mass of “dumb” malicious program we normally see.<cite><a href="http://www.securelist.com/en/blog/677/The_mystery_of_Duqu_Framework_solved">Kilde</a></cite></p></blockquote><p></p>]]></description>
<author>tormok</author>
<guid isPermaLink="true">http://newz.dk/tormok</guid>
<pubDate>Mon, 19 Mar 2012 20:32:58 +0100</pubDate>
</item>
<item>
<title>#4 - Mamad (moveax1ret)</title>
<link>http://newz.dk/ukendt-programmeringssprog-brugt-i-duqu-trojaner#4</link>
<description><![CDATA[<p></p><blockquote cite="bobske2 (#3)"><p>Ligner at det er compiled i msvc, men frameworket er nok deres eget<cite><a href="#3">bobske2 (#3)</a></cite></p></blockquote><p>Hvad giver dig det indtryk?</p><p>Jeg kan ikke se noget der tyder på det.........</p>]]></description>
<author>Mamad (moveax1ret)</author>
<guid isPermaLink="true">http://newz.dk/mamad-moveax1ret</guid>
<pubDate>Tue, 13 Mar 2012 08:25:33 +0100</pubDate>
</item>
<item>
<title>#3 - bobske2</title>
<link>http://newz.dk/ukendt-programmeringssprog-brugt-i-duqu-trojaner#3</link>
<description><![CDATA[<p>Ligner at det er compiled i msvc, men frameworket er nok deres eget</p>]]></description>
<author>bobske2</author>
<guid isPermaLink="true">http://newz.dk/bobske2</guid>
<pubDate>Tue, 13 Mar 2012 00:00:41 +0100</pubDate>
</item>
<item>
<title>#2 - T_A</title>
<link>http://newz.dk/ukendt-programmeringssprog-brugt-i-duqu-trojaner#2</link>
<description><![CDATA[<p>Det er da Aliens der har skrevet noget mystisk kode.</p>]]></description>
<author>T_A</author>
<guid isPermaLink="true">http://newz.dk/t_a</guid>
<pubDate>Mon, 12 Mar 2012 10:53:50 +0100</pubDate>
</item>
<item>
<title>#1 - Beetleburst</title>
<link>http://newz.dk/ukendt-programmeringssprog-brugt-i-duqu-trojaner#1</link>
<description><![CDATA[<p>Taleban har lavet den!<br/>Vi kvitterer lige med en ekstra bombe, med hilsnen: "Tak for sidst!"</p>]]></description>
<author>Beetleburst</author>
<guid isPermaLink="true">http://newz.dk/beetleburst</guid>
<pubDate>Sun, 11 Mar 2012 22:40:26 +0100</pubDate>
</item>
</channel>
</rss>
